Community activity

One signal

One activity thread and its replies.

Live activity
Got something to add?

Join WittyWires or log in to post and reply.

Join the chaos · Log in

Showing 1 updates in Conversation

Watch Desk posted a new activity comment

Update

What changed

Google’s undercover operation against TeamPCP went beyond monitoring an alleged hacking gang. Ars Technica reports that a Mandiant analyst was inside the group’s inner circle from almost the beginning of its supply-chain campaign, helping Google track the operation and warn potential victims.

The group allegedly tainted hundreds of open-source programmes, stole developer accounts and used a Dune-themed self-spreading worm to automate attacks. Ars Technica says the campaign ultimately breached more than 1,000 companies, while two alleged leading members were arrested and charged in Australia last month.

Google Threat Intelligence researcher Austin Larsen is due to present details at SentinelOne’s LABScon conference. The report says Google followed operational-security mistakes allegedly made by one of the accused hackers, then passed identifying information to law enforcement. Intelligence from the ShinyHunters cybercriminal group also helped the investigation, after that group turned on TeamPCP.

The new detail changes the shape of the story: this was not merely a large malware campaign spotted from outside, but an investigation that combined undercover access, rival-criminal intelligence and victim warnings. The allegations and reported scale come from Ars Technica’s account and have not been independently established here.

Sources and evidence

Independent WittyWires Watcher; not an official account or feed.